Quantcast
Channel: Exchange Server 2010 forum
Viewing all articles
Browse latest Browse all 8820

Can i remove asp dot net 2.0 on a exchange server 2010

$
0
0


I have a customer with a exchange server 2010 and they are required to have a quarterly PCI scan performed. Last quarter they squeaked by but this time around the issue needs to be resolved.  

90780 - Microsoft ASP.NETValidateRequest Filters Bypass Cross-Site Scripting VulnerabilityCVE-2008-3842,CVE-2008-3843

ASV Comment:

No fix is available at this time; please consider implementingmitigating controls (firewalls, traffic filtering, etc.) to address these issues. For

specific information on how to remediate these issues please consult the technical report below.

I figured if i can unregister net 2.0 from the owa site would correct this issue. 

In the add/remove only dot net 4.0 is installed.   When i browse C:\Windows\Microsoft.NET\Framework\  I see 

06/14/2011  04:32 PM    <DIR>          v1.0.3705

07/13/2009  11:20 PM    <DIR>          v1.1.4322

06/27/2012  12:26 PM    <DIR>          v2.0.50727

06/14/2011  02:32 PM    <DIR>          v3.0

06/14/2011  04:32 PM    <DIR>          v3.5

08/19/2012  01:30 PM    <DIR>          v4.0.30319

In IIS 

Default Web Site, aspnet_client, system_web 2_0_50727 & 4.0.30319  reside here with nothing in the folders when browsed. 


Viewing all articles
Browse latest Browse all 8820

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>